Skip to content

SignPlus for Confluence

Confluence page signing through Dokobit. The page is exported to PDF, signed by named signers, and the signed document is attached back to the page.

Atlassian reviews this documentation before the listing goes live, so there is nothing to install yet. Everything on this page and in the documentation is final.

The problem we solve

A signed PDF and the page it came from usually stop being the same document

Getting a Confluence page signed normally means exporting it by hand, sending the file somewhere, and filing the result. The signed PDF ends up in an inbox or a drive, and the page carries no record that it was signed at all.

The page also keeps moving. Confluence is built for editing, so the text a signer agreed to can be rewritten the same afternoon, and nothing in the signed file says which version it was.

SignPlus keeps both ends attached. The signing starts from the page, the signed document comes back as an attachment on that page, and the identity that was signed is a hash of the space, the page and its version number, so a later edit does not quietly inherit the signature.

What it does

What it does inside Confluence

Each one is a module in the app's Forge manifest rather than a description of intent.

01 · Under the page title

Start a signing without leaving the page

Sign this page, in the byline, opens the signing panel. Choose the signers, set a deadline and start the signing. The same byline later says whether the page has changed since it was signed.

02 · A whole department at once

Groups, sent in the background

Add a Confluence group as signers and every member is invited, up to 25,000 people on one signing. SignPlus sends it in the background, so closing the page does not stop it, and the signing details list who has not signed yet.

03 · The signed file returns on its own

No one has to go and fetch it

Dokobit calls the app when a signer acts or the status changes. Once the signed document has been downloaded from Dokobit, the app attaches it to the page it came from.

04 · The page as Confluence shows it

A document in your company's style

Panels, status lozenges, Jira work items tables, Oktul Work Item Selector fields and Jira Assets tables print the way the page draws them, with your font, logo, first page, header and footer.

05 · Configured once

Site settings, with per-space overrides where allowed

A site administrator sets the signing mode, the formats, the signing methods and what happens to the page while it is signed. A space administrator changes only what the site has opened to spaces, so a space cannot quietly point signing somewhere else.

06 · From outside Confluence

Start signings from flows and other systems

Two Jira automation actions, a REST API authenticated with an Atlassian service account, and webhooks that tell another system when a signing completes or a signed page is edited.

Setting it up

Installation runs through the product you already administer

There is no Oktul infrastructure to set up, which makes the application simpler to adopt.

  1. 1
    Choose the signing mode

    A new installation signs in Dokobit's test environment, where documents come back watermarked. Switch to your own Dokobit token before the first real signing.

  2. 2
    Decide what each space may change

    Every setting carries its own switch. Leave them off if signing must be identical everywhere.

  3. 3
    Open a page and select Sign this page under the title

    Add people or a group, choose the options, start the signing.

  4. 4
    Collect the signed PDF from the page

    It arrives as an attachment when the last signer has finished. Nothing has to be downloaded from Dokobit by hand.

Where it runs

Host platform and compatibility

Host productConfluence Cloud
SurfacesByline item and panel, Your signings page, site and space settings, Jira automation actions, REST API
RenderingForge native, UI Kit 2
RuntimeNode.js 24 on Forge
Signing providerDokobit
JiraOptional. Adds the automation actions, Assets tables and Work Item Selector cards
LicenceEnforced by the app on every entry point
Data handling and security

Page content leaves Atlassian, and here is exactly where it goes

SignPlus cannot do its job inside Atlassian alone: a qualified electronic signature is produced by a trust service provider. Dokobit is declared in the app's Forge manifest, which is the file Atlassian reviews, and a webhook address reaches nothing until your administrator approves it in Atlassian's own dialog, so neither is a matter of trust in this page.

Does page content leave Atlassian?
Yes, to Dokobit. This application declares egress, unlike Work Item Selector.
To which services?
*.dokobit.com, and any webhook address your administrator approves
What is sent to Dokobit?
The page rendered as a PDF, and each participant's name and email address.
Where is the PDF made?
Inside Atlassian's runtime. No third party renders it.
What else does it reach?
Only Atlassian's own hosts, and they receive nothing: your site and the avatar service for images, Atlassian's image library at dam-cdn.atl.orangelogic.com for the pictures in Atlassian's page templates, and api.atlassian.com to check a REST API caller's token.
What is stored in Forge?
One record per signing: the page's identity and hash, the Dokobit document token, the request's name and deadline and the page's prior restrictions, and one record per participant. A signing being sent is held as a job for 7 days. Never the document itself.
How is the signed version identified?
SHA-256 of the space, the page and its version number.
Who makes the signature?
The signer, on Dokobit's page, with their own eID. A qualified eID gives a qualified electronic signature (QES) under eIDAS, equal in law to a handwritten one across the EU. Oktul never sees a personal code or PIN.
Is Dokobit a qualified trust service provider?
Yes, for validating electronic signatures and seals. Dokobit states that it is supervised by Lithuania's Communications Regulatory Authority and listed on the EU Trusted List. Its compliance page at dokobit.com/compliance carries the certificates.
Where does Dokobit keep the data?
In the EU/EEA, mirrored in two locations, encrypted with TLS and AES-256, under ISO/IEC 27001 and 27018 certification audited by DNV, by Dokobit's own statement. The provider is Dokobit, UAB (registry code 301549834).
ScopeWhat it is for
read:page:confluenceRead the page being signed or exported.
read:confluence-content.allRead the page body in order to render it.
read:confluence-content.summaryReceive the page-edited event, so a signed page that changes can be reported.
write:confluence-contentRecord the signing against the page, and set and lift its restrictions.
read:confluence-content.permissionCheck the reader may act on the page before offering to sign it.
read:space:confluenceResolve the space a signing belongs to, and apply space settings.
readonly:content.attachment:confluenceList existing attachments on the page.
read:attachment:confluenceRead an attachment so it can be included in the document.
write:confluence-fileAttach the signed PDF back to the page.
read:confluence-userShow who initiated a signing, and who the signers are.
read:email-address:confluenceDokobit identifies a signer by email address, so the address of a signer you choose is read and sent.
read:cmdb-object:jiraRead the objects behind a Jira Assets table on a page, so they are in the document. Needs Jira connected.
read:content-details:confluenceMatch a signer named by email address to their Confluence account.
read:confluence-groupsOffer your groups as signers, and list a group's members when the signing is sent.
search:confluenceSearch a space's pages by title in the automation actions' page picker.
read:jira-workRead the work items in an Oktul Work Item Selector field, so they print as cards. Needs Jira connected.
storage:appStore the signing records and the settings.
Tested before each release

The tests every release has to pass

These figures belong to this application only. Suite sizes differ between applications.

Automated tests
1,359
Counted on the current build, including authorisation, injection and logging suites.
Test suites
68
Rendering, permissions, the REST API, automation, webhooks and licensing.
People per signing
25,000
After groups are expanded. Enforced on the page, in automation and in the REST API alike.
Questions

The questions other administrators ask most

Is a SignPlus signature legally binding?

Signed with a qualified eID, such as Smart-ID or an Estonian, Latvian, Lithuanian, Finnish or Belgian ID card, it is a qualified electronic signature, which Article 25(2) of eIDAS gives the legal effect of a handwritten signature in every EU member state. Dokobit's list of eIDs on dokobit.com says which methods produce one. Set E-signature levels to QES only to refuse the rest. A signing in test mode has no legal effect.

Who holds the relationship with the signing provider?

You do. Real signing runs on your own Dokobit account, with the token you enter in SignPlus. Test mode runs on Oktul's Dokobit sandbox so you can try SignPlus first, and what it signs is watermarked and binds nobody.

What happens if a signer never signs?

The signing keeps its status until everyone has signed or the deadline passes, and a strict deadline cancels it then. The signed document is attached to the page only once it exists.

Who can delete a finished signing?

A Confluence administrator, by default. The site can add space administrators, page editors or the person who started it. Deleting removes SignPlus's record; the signed file stays attached to the page.

Can a space administrator point signing somewhere else?

No. The signing mode is set for the whole site, and a space changes only the settings the site administrator has opened to spaces.

Does a lapsed licence stop a signing in progress?

No. New signings stop, but a signing already out for signature still completes, and its signed document is attached to the page.

Is this application in the Runs on Atlassian programme?

No, and it cannot be. That programme is for applications that keep all data inside Atlassian, and this one sends page content to a signing provider by design. Oktul Work Item Selector for Jira carries the badge; this application states its egress instead.
Pricing

Billed through the Atlassian Marketplace

Pricing, the free trial and billing run through the Marketplace, on the same terms as every other app on your site. The charge lands on your existing Atlassian invoice, so there is no new supplier to onboard, no purchase order and no security review of our payment handling.

The rest of the portfolio

Explore Oktul's other applications